Hi,

they are all visible in your admin interface - RPC help in the menu on the 
left.

The effects can be harmful to you, depending on how you use them and let
your visitors use them, which goes for any server-side scripting.

Sambar scripting is built with security in mind, because it's used to provide
the server admin.
One major advantage (disadvantage according to many others of course) is that
it doesn't allow file access - everything is wrapped inside functions, 
which takes
care of the specific task.

With netutils like these however, it can have various effects:
1) whois - if I request your whois page multiple times a second for a long 
period of time, you may run outof sockets, but you surely will be 
disconnected from the verisign whois server.

2) ping - I could have you ping x hosts all the time any time, simply by 
requesting the page you've setup.

3) iplookup - I could tie up your nameserver or piss of your provider 
simply by requesting the page multiple times and randomly generate names.

So - it all depends on what you allow the visitor to do - with these 
network utils, you'd be best of, if you require registration and Fair Use 
policy agreement, prior to usage, so you can sue people, when you get 
blamed for something they did - or - use them under the hood, without the 
user being able to access variables.

What goes for any server-software: throw away the pre-installed samples, 
prior to putting it into production - they are ment to get one acquinted 
with the server, which usually is the opposite of secure programming.

Hope this helps,

nyem said at 20:43 22-5-2002:

>Hello,
>
>Apart from the 3 RCX samples that come with Sambar (ping,whois & 
>iplookup), what other directives we can use?
>
>would using them on my site cause any harmful effect on my server performance?
>
>please advise
>
>regards,
>nyem
>
>-------------------------------------------------------
>To unsubscribe please go to http://www.sambar.ch/list/
>
>
>
>
>
>
>
>
>---
>Incoming mail is certified Virus Free.
>Checked by AVG anti-virus system (http://www.grisoft.com).
>Version: 6.0.363 / Virus Database: 201 - Release Date: 21-5-2002

____________________________________________________

</MELVYN>

void wakeup()
{
         for(long int cuppajava;drink();cuppajava++);
}

-------------------------------------------------------
To unsubscribe please go to http://www.sambar.ch/list/


Reply via email to